Delinea: Ransomware Back on Rise, With Cloud Targeted Most

Ransomware Continues to Pose a Threat for Businesses
Report From Delinea Finds Ransomware Attacks Continue to Rise, With Over 75% of Organisations Paying up, as Cloud Becomes the Most Vulnerable Attack Vector

Consistently among the top concerns for IT professionals, ransomware attacks may not be at the levels seen in 2021 but are still continuing to rise, according to research from Privileged Access Management provider Delinea.

The company’s annual State of Ransomware report shows that the familiar tactics of crippling a company and holding it hostage have been replaced by new strategies that use stealth to exfiltrate private and sensitive data. Cybercriminals then frequently threaten to sell it to the highest bidder on the darknet or leverage it to reap a handsome cyber insurance payment.  

The report found that the number of organisations claiming to have been a victim of ransomware in the past 12 months more than doubled since 2023, from 25% to 53%. Mid-sized companies appeared to be in cybercriminals’ crosshairs the most, with 65% stating they had been a ransomware victim over the past 12 months. Organisations are also paying ransoms more frequently, up to 76% from 68% the prior year. 

“Ransomware certainly appears to have reached a critical sea change – it's no longer just about the quick and easy payout,” said Rick Hanson, President at Delinea. “Even as organisations are investing more in safety nets like cyber insurance which often have ransomware payouts included in coverage policies, cybercriminals are finding that using stealth tactics to stay under the radar and access sensitive, valuable information to sell is the better investment of their effort.”

Ransomware threat actors employing new tactics

More striking, however, are the emerging trends in motivations, strategies, and tactics that the survey revealed. Data exfiltration registered a surge of 39% (reported by 64% of respondents, up from 46%) and became a preferred goal for the attackers, who are now gaining control of a company’s network to download sensitive data to sell on the darknet. This trend is also evidenced by the significant downturn of traditional money grabs as the main motivation (34%, down from 69% the year before). 

As their main goals changed, cyber criminals modified their tactics and moved away from using email as a preferred attack vector (down from 52% to 37%), targeting cloud (44%) and compromised applications (39%) instead. By taking a more covert approach, attackers can remain undetected longer and gain continuous access to systems and data, enabling them to ramp up the damage when they choose.  

Contrasting trends emerged around the measures organisations have in place against ransomware. While 91% indicated they have specific budget allocations for ransomware, up from 68% in 2022, only 61% (down from 76%) said security budgets were allocated following an attack, which could be due to economic uncertainty or tighter budgets. Despite feeling they could bolster defences by spending more on critical areas like Privileged Access Management (28%, up from 16%), respondents seemed to lack clarity on how increased spending would help improve security. On a positive note, executives and boards are now listening as 76% reported that their leadership is concerned about ransomware, but perhaps only after an attack.  

“The changing strategies and tactics in ransomware attacks require a layered approach to security that mitigates the risk of unauthorised access, even when credentials are compromised,” said Joseph Carson, Advisory CISO and Chief Security Scientist at Delinea. “It also shows the critical role privileged access plays in overall cybersecurity postures.”

******

Make sure you check out the latest edition of Technology Magazine and also sign up to our global conference series - Tech & AI LIVE 2024

******

Technology Magazine is a BizClik brand

Share
Share

Featured Articles

Rimini Street: The Need for IT Leaders to Deliver ROI

As IT costs soar and budgets tighten, CFOs & CIOs are forging closer partnerships to ensure technology investments deliver value and drive business growth

Amazon in Europe: Committing to German Cloud & AI Expansion

Tech giant Amazon commits to a billion-dollar investment in Germany, Europe's biggest economy, as demand for AI and cloud services continues to surge

Gen AI Boom Drives Nvidia Value to Overtake Microsoft

Nvidia surpasses Microsoft to become the most valuable company, with its AI and chip developments tripling stock and prompting a US$3.3tn market cap

IBM & Wimbledon: AI Is Changing the Game for Sports

AI & Machine Learning

Zoom: Powering EMEA with a Partner-Led Focus

Digital Transformation

Schneider Electric: UK&I President Grows Her Europe Presence

Digital Transformation